56.580 CVE seguite
773 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
Vulnerabilità Microsoft
15.463 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2020-1034 | MED 6.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.</p> <p>To exploit the vulnerability, a locall | 4,9% | — |
| CVE-2019-1183 | HIGH 8.8 | microsoft windows_10 This information is being revised to indicate that this CVE (CVE-2019-1183) is fully mitigated by the security updates for the vulnerability discussed in CVE-2019-1194. No update is required. | 4,8% | — |
| CVE-2019-1302 | HIGH 8.8 | microsoft asp.net_core An elevation of privilege vulnerability exists when a ASP.NET Core web application, created using vulnerable project templates, fails to properly sanitize web requests, aka 'ASP.NET Core Elevation Of Privilege Vulnerability'. | 4,8% | — |
| CVE-2020-1469 | HIGH 7.5 | microsoft bond A denial of service vulnerability exists when the .NET implementation of Bond improperly parses input, aka 'Bond Denial of Service Vulnerability'. | 4,8% | — |
| CVE-2004-0540 | HIGH 10.0 | microsoft windows_2000 Microsoft Windows 2000, when running in a domain whose Fully Qualified Domain Name (FQDN) is exactly 8 characters long, does not prevent users with expired passwords from logging on to the domain. | 4,8% | — |
| CVE-2000-0519 | LOW 2.6 | microsoft ie Internet Explorer 4.x and 5.x does not properly re-validate an SSL certificate if the user establishes a new SSL session with the same server during the same Internet Explorer session, aka one of two different "SSL Certificate Validation" vulnerabilities. | 4,8% | — |
| CVE-2000-0518 | LOW 2.6 | microsoft ie Internet Explorer 4.x and 5.x does not properly verify all contents of an SSL certificate if a connection is made to the server via an image or a frame, aka one of two different "SSL Certificate Validation" vulnerabilities. | 4,8% | — |
| CVE-2001-0860 | HIGH 7.5 | microsoft windows_2000 Terminal Services Manager MMC in Windows 2000 and XP trusts the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers, which allows clients to spoof their public IP address, e.g. through a Network Address Tr | 4,8% | — |
| CVE-2019-1096 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. | 4,8% | — |
| CVE-2020-16932 | HIGH 7.8 | microsoft 365_apps <p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If t | 4,8% | — |
| CVE-2020-16931 | HIGH 7.8 | microsoft 365_apps <p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If t | 4,8% | — |
| CVE-2022-30155 | MED 5.5 | microsoft windows_10 Windows Kernel Denial of Service Vulnerability | 4,8% | — |
| CVE-2020-1510 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the win32k component improperly provides kernel information. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerab | 4,8% | — |
| CVE-2022-21984 | HIGH 8.8 | microsoft windows_10 Windows DNS Server Remote Code Execution Vulnerability | 4,8% | — |
| CVE-2001-0281 | HIGH 7.2 | microsoft windows_nt Format string vulnerability in DbgPrint function, used in debug messages for some Windows NT drivers (possibly when called through DebugMessage), may allow local users to gain privileges. | 4,8% | — |
| CVE-2017-0299 | MED 5.0 | microsoft windows_10 The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a spe | 4,8% | — |
| CVE-2017-0221 | HIGH 7.5 | microsoft edge A vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0227 and CVE-2017-0240. | 4,8% | — |
| CVE-2018-0976 | MED 5.3 | microsoft windows_10 A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka "Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability." This affects W | 4,8% | — |
| CVE-2021-21139 | MED 6.5 | google chrome Inappropriate implementation in iframe sandbox in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. | 4,7% | — |
| CVE-2018-8320 | MED 4.3 | microsoft windows_10 A security feature bypass vulnerability exists in DNS Global Blocklist feature, aka "Windows DNS Security Feature Bypass Vulnerability." This affects Windows Server 2012 R2, Windows Server 2008, Windows Server 2012, Windows Server 2019, Windows Server 2016, Wi | 4,7% | — |
| CVE-2023-29358 | HIGH 7.8 | microsoft windows_10_1507 Windows GDI Elevation of Privilege Vulnerability | 4,7% | — |
| CVE-2004-2704 | MED 4.3 | hastymail hastymail Hastymail 1.0.1 and earlier (stable) and 1.1 and earlier (development) does not send the "attachment" parameter in the Content-Disposition field for attachments, which causes the attachment to be rendered inline by Internet Explorer when the victim clicks the | 4,7% | — |
| CVE-2002-0443 | MED 4.6 | microsoft windows_2000 Microsoft Windows 2000 allows local users to bypass the policy that prohibits reusing old passwords by changing the current password before it expires, which does not enable the check for previous passwords. | 4,7% | — |
| CVE-2017-0191 | MED 5.8 | microsoft windows_10 A denial of service vulnerability exists in the way that Windows 7, Windows 8.1, Windows 10, Windows Server 2008 R2, Windows Server 2012, Windows Server 2012 R2, and Windows Server 2016 handles objects in memory. An attacker who successfully exploited the vuln | 4,7% | — |
| CVE-2026-40369 | HIGH 7.8 | microsoft windows_11_24h2 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | 4,7% | — |